ZeroHour

CVE-2025-40597

large

Heap Buffer Overflow in SonicWall SMA100 Series Web Interface (DoS, Possible RCE)

CVSS 3.1
7.5 high
EPSS
29%p98
Published
()
Modified
AI analysis

CVE-2025-40597 is a heap-based buffer overflow (CWE-122) in the web interface of SonicWall's SMA100 series appliances. Because the flaw is reachable over the network without credentials or user interaction, a remote, unauthenticated attacker can send crafted requests to the appliance web interface to trigger it. A successful attack can crash the device, causing a denial of service, and may potentially escalate to arbitrary code execution on the appliance. Any organization running an affected SMA100-series appliance (SMA 210, SMA 410, or SMA 500v) with its web interface reachable by untrusted users is in scope, since these devices typically sit at the network edge as SSL VPN gateways. No public proof-of-concept or confirmed in-the-wild exploitation is currently known, but the EPSS score of 29.4% (98th percentile) indicates a high likelihood of exploitation within the next 30 days.

What to do: Update SMA 210, SMA 410, and SMA 500v appliances to the patched firmware specified in SonicWall's security advisory (no fixed version numbers were provided in the available data). Until patching is complete, restrict access to the appliance web interface (management UI) to trusted management networks or IP allowlists, since unauthenticated network access is the attack path. Given the high EPSS probability of exploitation within 30 days, prioritize internet-facing devices, verify current firmware versions against the advisory, and monitor logs for crashes or unexpected appliance restarts.

Affected
sonicwall SMA 210 firmware
sonicwall SMA 410 firmware
sonicwall SMA 500v firmware
Estimated exposure
large≈ tens of thousands (10,000–50,000) of internet-exposed SMA 100-series appliances — SonicWall SMA 100-series appliances are widely deployed as internet-facing SSL VPN gateways at small and mid-sized organizations, and public internet scan datasets typically show tens of thousands of these devices exposed on the open…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.

Vendors
sonicwall
Products
sma 500v firmware, sma 210 firmware, sma 410 firmware
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news